CVE-2026-3276 on CTRL-OS 26.05
Aliases: CVE-2026-3276
Packages: python313
Status: Plausible, Resolved
Advisory Information
unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.
Updates
2026-07-23 16:02 CEST
Metadata changes:
- Status for package
python313: “Resolved” (fff38d56fb8e15a140da141149c596766b838d0b)
(Amended on: 2026-07-23 16:14 CEST)
2026-07-23 16:02 CEST
Metadata changes:
- Status for package
python314: “Resolved” (b907b8ba5e335b35aed7b8b2d2f2058d8f10e055)
(Amended on: 2026-07-23 16:14 CEST)
2026-07-23 16:02 CEST
Metadata changes:
- Status for package
python315: “Resolved” (597ad40f1206472be8823406acdf51bf24cb2899)
(Amended on: 2026-07-23 16:15 CEST)
2026-07-23 16:01 CEST
Metadata changes:
- Status for package
python311: “Plausible” - Status for package
python312: “Plausible” - Status for package
python313: “Plausible” - Status for package
python314: “Plausible” - Status for package
python315: “Plausible”
2026-06-04 00:03 CEST
Metadata changes:
- Status for package
python311: “New” - Status for package
python312: “New” - Status for package
python313: “New” - Status for package
python314: “New” - Status for package
python315: “New”
(Amended on: 2026-06-04 00:04 CEST)